CVE-2026-26337

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
Configurations

No configuration.

History

20 Feb 2026, 15:20

Type Values Removed Values Added
References
  • () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 -

19 Feb 2026, 18:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 18:24

Updated : 2026-02-20 15:20


NVD link : CVE-2026-26337

Mitre link : CVE-2026-26337

CVE.ORG link : CVE-2026-26337


JSON object : View

Products Affected

No product.

CWE
CWE-36

Absolute Path Traversal